# shuvonsec

> Open-source publisher. Listings imported from github.com/shuvonsec — credited to the original author with their license.

- **Listings:** 11
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/shuvonsec
- **Website:** https://github.com/shuvonsec

## Published listings

- [Web3 Ai Tools](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-ai-tools) — Skill · Free — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-ai-tools`
  AI-powered tools for Web3 bug bounty automation. Use when you want to automate recon, run autonomous audits, or use AI agents for vulnerability discovery.
- [Web3 Triage Report](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-triage-report) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-triage-report`
  Bug triage validation system, Immunefi report format, and 20 real paid bounty examples dissected. Use this when validating a finding before submitting, writing an Immunefi report, checking if a bug is actually valid, or studying real examples of paid vulnerabilities.
- [Web3 Hunt Zksync Era](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-hunt-zksync-era) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-hunt-zksync-era`
  ZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a target. Contains architecture breakdown, 25 tested attack vectors, and pre-dive scoring refinements for large L1 bridge protocols.
- [Web3 Hunt Foundation](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-hunt-foundation) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-hunt-foundation`
  Hunter mindset, recon setup, and target scoring for Web3 bug bounty. Use at the START of any new protocol hunt - scoring targets, setting up environment, understanding architecture.
- [Web3 Bug Classes](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-bug-classes) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-bug-classes`
  Complete reference for all 10 DeFi smart contract bug classes. Use this when hunting for specific vulnerability types, need attack patterns for accounting desync, access control, incomplete path, off-by-one, oracle manipulation, ERC4626 vaults, reentrancy, flash loans, signature replay, or proxy/upgrade bugs.
- [Web3 Methodology Research](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-methodology-research) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-methodology-research`
  External research synthesis from Trail of Bits, SlowMist, ConsenSys, Immunefi, and Cyfrin. Use this for advanced audit methodology, Echidna/Medusa fuzzing setup, Slither custom detector writing, attack pattern deep dives, or the 4-phase learning roadmap.
- [Web3 Case Study Role Misconfig](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-case-study-role-misconfig) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-case-study-role-misconfig`
  Case study - role misconfiguration bug class applied to a yield aggregator protocol. Use as a template for applying all 10 bug classes to a single target.
- [Web3 Grep Arsenal](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-grep-arsenal) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-grep-arsenal`
  Master grep command arsenal for Web3 smart contract auditing. Use when starting a new protocol scan, before deep code review, or when hunting specific vulnerability classes.
- [Web3 Solidity Audit Mcp](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-solidity-audit-mcp) — Skill · Free — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-solidity-audit-mcp`
  MCP server integrating Slither + Aderyn + SWC patterns into Claude Code for smart contract auditing. Use when analyzing Solidity files, running DeFi-specific detectors, or generating invariants. 10 MCP tools, 86 SWC detectors, DeFi preset pack, CI/CD workflow.
- [Web3 Start Here](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-start-here) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-start-here`
  Master index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT.
- [Web3 Poc Foundry](https://agentstack.voostack.com/l/skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-poc-foundry) — Skill · Free · security-reviewed — `agentstack add skill-shuvonsec-web3-bug-bounty-hunting-ai-skills-web3-poc-foundry`
  Complete Foundry PoC writing guide + all cheatcodes + DeFiHackLabs reproduction patterns. Use this when building a proof of concept exploit, setting up a fork test, using Foundry cheatcodes, or reproducing a known DeFi hack for learning.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
